Notes:
- COSO Framework (Committee of Sponsoring Organizations):Â The global gold standard for internal controls. It consists of five interrelated components:
- Control Environment:Â The tone at the top, ethics, and organizational structure.
- Risk Assessment:Â Identifying and analyzing risks that could prevent the achievement of objectives.
- Control Activities:Â Policies and procedures (e.g., approvals, reconciliations, segregation of duties) to mitigate risks.
- Information & Communication:Â Ensuring relevant information flows up, down, and across the organization.
- Monitoring Activities:Â Ongoing evaluations and separate assessments to determine if controls are working.
- Sarbanes-Oxley (SOX) Section 404:
- Management Assessment:Â CEOs and CFOs must certify the effectiveness of internal controls over financial reporting (ICFR).
- Auditor Attestation:Â External auditors must independently attest to management’s assessment (for large accelerated filers).
- Material Weaknesses:Â A deficiency where there is a reasonable possibility that a material misstatement of financial statements will not be prevented or detected. Must be disclosed publicly.
- Segregation of Duties (SoD):Â A fundamental control principle where incompatible duties are separated (e.g., the person authorizing a payment cannot be the same person recording it or holding the cash). This prevents fraud and error.
- Continuous Monitoring:Â Moving from periodic testing to real-time monitoring using data analytics and automated controls.